Thursday, March 28, 2024

Microsoft Released Security Updates for Internet Explorer zero-day

Microsoft released security updates for remote code exection vulnerability that exists with Internet explorer, which allows an attacker to execute an arbitary code in the context of the current user.

The vulnerability is tracked as CVE-2018-8653. It was identified by Google’s Threat Analysis Group and the vulnerability is currently being exploited in wild.

Microsoft  recently released Security Updates & Fixed 39 Vulnerabilities Including Active Zero-day

The bug can be exploited if the user visited a specially crafted webpage that was designed to exploit the vulnerability through Internet Explorer browser.

An attacker who has successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged in with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

If the attacker takes control over the system, they can utilize it to download additional malware and execute the malware with user access.

The vulnerability could corrupt the memory, which allows an attacker to run the an arbitary code remotely. Now Microsoft fixed the Zero-day by modifying the script engine that handles the object.

To fix the vulnerability, Microsoft released a Cumulative security update for Internet Explorer KB4470199 allowing the users to confirm the update by verifying the version of jscript.dll is 5.8.9600.19230.

This update is applicable to Internet Explorer 11 on Windows 10, Internet Explorer 11 on Windows 8.1 Update, Internet Explorer 11 on Windows 7 SP1, Internet Explorer 10 on Windows Server 2012, Internet Explorer 9 – Windows Embedded Standard 2009 & Windows Embedded POSReady 2009..

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Website

Latest articles

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus Labs, the leading Web3 security infrastructure provider, has unveiled a groundbreaking report highlighting...

Wireshark 4.2.4 Released: What’s New!

Wireshark stands as the undisputed leader, offering unparalleled tools for troubleshooting, analysis, development, and...

Zoom Unveils AI-Powered All-In-One AI Work Workplace

Zoom has taken a monumental leap forward by introducing Zoom Workplace, an all-encompassing AI-powered...

iPhone Users Beware! Darcula Phishing Service Attacking Via iMessage

Phishing allows hackers to exploit human vulnerabilities and trick users into revealing sensitive information...

2 Chrome Zero-Days Exploited at Pwn2Own 2024: Patch Now

Google has announced a crucial update to its Chrome browser, addressing several vulnerabilities, including...

The Moon Malware Hacked 6,000 ASUS Routers in 72hours to Use for Proxy

Black Lotus Labs discovered a multi-year campaign by TheMoon malware targeting vulnerable routers and...
Guru baran
Guru baranhttps://gbhackers.com
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Mitigating Vulnerability Types & 0-day Threats

Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities.

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

Related Articles